skip to content

Segmentation & Microsegmentation

You will learn how to carve a network into zones — VLANs, DMZs, private VLANs — and how microsegmentation extends that to per-workload east-west policy with security groups. Interviewers probe it with 'design a network for X' questions, since segmentation is the primary blast-radius control after a breach.

on this pageshow

explore

questions

page 1 of 2

A segment allow-list built from 30 days of observed flows permits an intruder's sessions too - why can the records not tell them apart?

level: juniorimportance: must knowfreq 58%

answer

  1. descriptive, not normative
  2. five-tuple and counters only
  3. no payload, no user, no purpose
  4. present is not the same as normal
  5. intent is asserted by a human, never observed

basics

~20 s

A flow record only says bytes moved between two endpoints on a port. It carries no payload, no user and no purpose, so a compiler turning records into permits cannot separate a designed dependency from an intruder who was present.

solid answer

~50 s

A flow export is descriptive, not normative. Each record carries a five-tuple, byte and packet counters and start/end timestamps - and nothing about who asked for the traffic or why it exists. Compiling 30 days of records into permits therefore produces a list of what *happened*, and the only property every entry shares is that it occurred inside your window. An adversary resident before the capture began contributes flows that look exactly like a historian poll: modest volume, regular timing, a plausible port. The honest claim after enforcement is "this segment now denies anything that was not present during the window", not "this segment permits only authorised traffic". Turning the first sentence into the second costs human time: someone has to state, per flow, what it is for - and on a plant floor most flows have no such person.

code

text · 12 lines
text
flowStartMilliseconds:    2026-03-04 02:11:07.412
flowEndMilliseconds:      2026-03-04 02:19:55.031
sourceIPv4Address:        10.42.8.19
sourceTransportPort:      51402
destinationIPv4Address:   10.42.3.7
destinationTransportPort: 502            # Modbus/TCP
protocolIdentifier:       6              # TCP
octetDeltaCount:          48219
packetDeltaCount:         611
ingressInterface:         7
...
# absent: payload, user, process, application name, and any reason this flow exists

go deeper

for a junior

Be ready to state what a flow record does and does not contain, and to say out loud that a permit derived from one proves only that the traffic occurred.

for a middle

Explain the compiling step - distinct five-tuples become permits - and why a resident adversary's sessions satisfy every criterion the compiler applies.

for a senior

Show that you would fix the claim before you fix the list: state precisely what the enforced segment denies, and refuse the sentence that says permitted equals authorised.

for a principal

Own the consequence for assurance and contracts: if intent cannot be observed, it must be procured, and that means specifying interface documentation as a deliverable rather than reconstructing it later.

## What a derived allow-list is A team inherits a flat plant network - controllers, a historian, an MES, engineering workstations, all reachable from each other - and is told to segment it. Nobody has a dependency diagram. The standard move is to observe first: put a passive vantage in the path (a mirror port, or flow export from the aggregation switches), collect for a few weeks, then compile the distinct source/destination/port/protocol combinations into permits. That compiled set becomes the first policy the segment has ever had. The technique is sound as a *starting point*. The mistake is what people believe the output is. ## What is actually in the record A NetFlow or IPFIX record is a summary of a conversation, keyed on the five-tuple. Typical fields: `sourceIPv4Address`, `destinationIPv4Address`, `sourceTransportPort`, `destinationTransportPort`, `protocolIdentifier`, `octetDeltaCount`, `packetDeltaCount`, `flowStartMilliseconds`, `flowEndMilliseconds`, an interface index, and on some templates the union of TCP flags seen. That is the entire input the compiler had. What is *not* in it: - **The payload.** Flow records prove bytes moved; they never show what the bytes were. A permit derived from one says nothing about the application riding the port. - **A user or process.** No account, no binary, no service identity. - **A purpose.** There is no field for "this exists because the MES polls tag values every 5 seconds". Intent is never observed; it is only ever asserted by a human. - **Authorisation.** No one consented to any of this. The traffic simply ran. ## The three things observation cannot establish **1. That a flow was intended.** A misconfiguration that has run for six years is indistinguishable from a designed dependency. Both are steady, both are old, both appear in every daily bucket. **2. That a flow is correct.** An engineering workstation reaching a controller directly instead of through the intended gateway looks like a first-class dependency to the compiler, because it is a real, repeated, high-count flow. **3. That the estate was clean when you looked.** This is the one that matters for security. The window is a *sample of what was present*, not a definition of what is normal. If an adversary held sessions during those 30 days - a jump host into the historian, the historian onward to controllers - those sessions are flows, they meet every criterion the compiler applies, and they become permits. Observation cannot distinguish "normal" from "present", because presence is the only evidence it has. ## Direction is an inference too People assume the record tells them who initiated. For TCP it often does - the flow start and the port pattern usually identify the client, and the flag union helps - but a long-lived session that was already open when export began, or a session that restarted mid-window, can be attributed backwards. UDP has no handshake at all, so initiator is inferred from timing and port role. Getting direction wrong in a derived rule means permitting the reverse of what actually happens, which is exactly the direction an intruder wants. ## What the technique does buy you It is not worthless - it is the difference between a flat network and a narrowed one. After enforcement, anything that did *not* appear in the window is denied. A new foothold reaching for a path nobody used is stopped. Flows are enumerated, which is more than the plant had yesterday. Those are real claims and you should make them. ## The price of upgrading the claim To move from "was observed" to "is authorised" you need an owner per flow who can state what it is for. That is a human campaign, not a tooling problem, and on an industrial estate most flows have no such owner: the integrator who commissioned the line left years ago, the contract never required an interface specification, and the people who remain will not sign a statement about traffic they did not design. That is why derived lists are so often adopted unread - not because engineers are lazy, but because nobody will accept the outage risk of deleting a line they cannot explain. ## How to answer in an interview Say plainly: a permit derived from a flow record proves the flow happened, nothing more. Then name the consequence - if an intruder was inside during the window, you have just written their access into policy - and then name the cost of doing better, which is per-flow intent attribution.

  • So what claim can you honestly make to the plant owner the day the derived policy is enforced?
    That the segment now denies any traffic that did not occur during the observation window, which meaningfully narrows a previously flat network and stops a new foothold from reaching paths nobody used. You cannot claim that permitted traffic is authorised, that every conduit has a purpose, or that anyone already inside has been constrained. Say the first sentence and refuse the rest.
  • Two flows look identical in the export - same ports, similar volume, both daily. What would actually separate them?
    Only something outside the record: a named owner who can state which application produces it and what breaks if it stops, a change or commissioning record that introduced it, or an asset register entry that makes one endpoint's role explicit. Volume, regularity and age are not evidence of legitimacy - an established intruder's traffic is steady, regular and old too.

Watching a building's doors for a month tells you which doors got used. It does not tell you which people were supposed to be inside, and it will happily issue a key to the burglar who came and went all month.

saying these in an interview costs you the question

  • Treats thirty days of traffic as a definition of normal
  • Says the flow export shows what the traffic contained
  • Assumes long-running and high-volume implies legitimate
  • Claims the derived list permits only authorised traffic
  • Believes direction of a UDP flow is recorded rather than inferred

context

open as a page

An infusion pump takes no patch or agent: what still constrains an attacker who lands on it, and what does that cost?

level: juniorimportance: must knowfreq 62%

basics

~20 s

You cannot fix the host, so the only control is what the segment permits it to originate and receive. The price is a standing exception with a named owner and a renewal date, and an intruder who lands there inherits it.

open as a page

All 900 hotel guest rooms sit in one VLAN — what does a compromised laptop there reach without ever crossing the firewall?

level: juniorimportance: must knowfreq 70%

basics

~20 s

Every other host in that VLAN — with three devices a room, roughly 2,700 of them. Traffic between hosts in one broadcast domain is switched, never routed, so the inter-VLAN firewall neither filters nor logs it.

open as a page

Every segment is permitted to the same DNS, time, directory and log services and cannot function without them — why does an adversary who takes one of those hosts defeat the segmentation?

level: juniorimportance: must knowfreq 62%

basics

~20 s

That permission already exists in every segment's rule set. Segmentation limits who may reach whom, but the shared tier is exempt by design, so owning it hands an adversary an approved path into every segment.

open as a page

What does approving one microsegmentation allow rule prove about what an intruder on that workload reaches?

level: juniorimportance: must knowfreq 60%

basics

~20 s

Almost nothing. It proves one named source group may reach one destination on those ports. What an intruder reaches is the union of every allow covering that workload's groups, then the same from each host it lands on.

open as a page

A zone diagram shows a firewall between two subnets that traffic no longer traverses - what does an intruder gain, and what has to move?

level: juniorimportance: must knowfreq 64%

basics

~20 s

A diagram is a claim, not a control. If routing carries the traffic around the firewall, an intruder crossing between those subnets meets no filter at all. Only moving the enforcement point onto the real path fixes it, and that costs a change window.

open as a page

Why is a firewall rule export not evidence that a segment boundary actually denies traffic?

level: juniorimportance: must knowfreq 55%

basics

~20 s

A rule export shows intent, not effect. It cannot show whether the traffic ever reaches that device, whether an earlier or later rule matches first, or whether the device is in the path at all. Only traffic originated from inside the segment produces an outcome.

open as a page

An intruder pivots between two PCs on one flat office VLAN - why does the perimeter firewall log nothing, and what would have to change first?

level: juniorimportance: must knowfreq 72%

basics

~20 s

Two hosts in the same subnet talk directly through the switch and never reach the default gateway, so a border firewall is simply not on that path and records nothing. Only splitting them into separately routed subnets puts a device in the way.

open as a page

Microsegmentation cut hundreds of real flows: what does it still not remove from an intruder on a valid session?

level: juniorimportance: must knowfreq 62%

basics

~10 s

It removes destinations, not authority. An intruder driving a working, authenticated session keeps every permission that account already held; segmentation only shortens the list of places the account can be used from.

open as a page

An intruder gets a session on your firewall's management console — what does that let them do that evading the firewall never would?

level: juniorimportance: must knowfreq 62%

basics

~20 s

They rewrite the policy instead of slipping past it. A permit they add is enforced as legitimate, the traffic that follows looks authorised in every downstream record, and the device's local change log is theirs to edit too.

open as a page

How does an intruder already resident in a plant network end up holding a permanent permit in a flow-derived segment policy?

level: middleimportance: must knowfreq 46%

basics

~20 s

Their sessions run during the observation window, so the compiler writes them into the allow-list as ordinary flows. On enforcement day only missed legitimate flows break and get attention; the intruder's path breaks nothing, so nobody looks.

open as a page

In label-keyed segmentation, what does an attacker who can write a workload's label gain over one who can only send packets?

level: middleimportance: must knowfreq 50%

basics

~20 s

They stop attacking the boundary and become an allowed party. Policy grants reachability to the label, so a successful tag write buys permitted, ordinary-looking flows with no packet crafting. The tagging API is now the segmentation boundary.

open as a page

How does subnetting a flat office VLAN create an interior chokepoint against an intruder, and what does that new hop cost?

level: middleimportance: must knowfreq 58%

basics

~20 s

Splitting one subnet into several forces traffic between them to a default gateway, and a policy applied at that routed hop is the first thing an intruder's lateral movement must cross. The cost is hairpinned traffic, added latency, a new failure domain and full re-addressing.

open as a page

A red team crossed your 40,000-rule microsegmentation policy using only approved allows - how do you recover a set you can state?

level: seniorimportance: must knowfreq 52%

basics

~20 s

Stop trying to read the rules. State a short list of pairs that must never be reachable, compute effective reachability over rule text and current membership, test those invariants on every change, and show reviewers the reach delta.

open as a page

An address-keyed allow rule in a fleet that recycles IPs hourly: what can an attacker inherit, and what does label-keying cost?

level: juniorimportance: should knowfreq 55%

basics

~20 s

Nothing binds an IP to a workload. When an instance dies its address returns to the pool, and whatever lands on it next inherits every rule that named it. Label-keying moves that trust onto an issuance path you now run.

open as a page

Segment rules for an unpatchable imaging modality are keyed to its fixed IP. How can an attacker inherit that permit?

level: middleimportance: should knowfreq 45%

basics

~20 s

An address-keyed permit trusts a field in the packet, not an identity the device proves, so whoever answers at that address inherits it. Holding the binding true costs static addressing, a hand-kept register and change coordination on every device swap.

open as a page

Private VLAN isolation stops guest-to-guest attacks, yet DHCP still works and casting to the room screen fails — why?

level: middleimportance: should knowfreq 45%

basics

~20 s

An isolated port may exchange frames only with promiscuous ports, where the gateway and the address relay sit — so assignment still completes. Two guest devices are both isolated, so the host-to-host discovery casting depends on is dropped.

open as a page

Segments may reach the shared resolver, directory and log collector outbound only, and the permit cannot be narrowed — what does an adversary who owns one of those hosts still reach?

level: middleimportance: should knowfreq 48%

basics

~10 s

Everything that asked. A stateful permit carries replies back inside the same connection, so a hostile service answers every client in every segment. Outbound-only constrains who starts the conversation, never who supplies the content.

open as a page

How can a workload gain new microsegmentation reach with no rule change and no reviewer seeing it?

level: middleimportance: should knowfreq 46%

basics

~20 s

By joining a group. Policy is written against groups and compiled per virtual NIC, so a tag set by build automation, in a change queue no reviewer watches, grants every existing rule naming that group.

open as a page

Your zone firewall exports no flow for a busy subnet pair - how do you tell a bypass an intruder can use from missing collection before booking a window?

level: middleimportance: should knowfreq 46%

basics

~20 s

Absence of flow records is ambiguous: it means the device never saw the traffic, or that export was never configured, sampled it away, or dropped it. Confirm the forwarding path itself before you claim a bypass, because the claim buys an outage window somebody has to authorise.

open as a page

Your segmentation probe to another segment times out - what different situations does that one result hide?

level: middleimportance: should knowfreq 46%

basics

~20 s

A timeout proves only that no reply came back. It covers a filter silently discarding the packet, the packet never reaching the enforcing device at all, and the packet arriving at a destination that was off or not listening while the reply was dropped. A pass and a broken probe look identical.

open as a page

What does a host policy agent distinguish about an intruder's session that a segment boundary cannot, and what does it cost to run?

level: middleimportance: should knowfreq 47%

basics

~20 s

On the wire the session is just an allowed address pair; on the workload an agent can tie the rule to the process that opened it. It still cannot see who drives that process, and it must run everywhere.

open as a page

Your firewall, sensor and access-control consoles authenticate admins against the same corporate directory as email — what does an intruder holding one group membership reach?

level: middleimportance: should knowfreq 50%

basics

~20 s

Everything those consoles trust. Device-administration AAA hands the logon decision to the directory, so one account in the right group is an administrator on the firewall, the sensor and the access-control policy at the same time.

open as a page

3,000 permits were derived from plant-floor flows and no integrator will state intent - how do you find owners before you bless an intruder's path?

level: seniorimportance: should knowfreq 40%

basics

~20 s

Stop asking whether a flow is needed - the answer is always yes. Attribute assets rather than flows, collapse permits into repeated patterns, spend effort on boundary-crossing ones, and register the unattributable residue with a named owner.

open as a page

Workloads can call the tagging API to label themselves and policy trusts it — how do you fix issuance, and what does running it cost?

level: seniorimportance: should knowfreq 45%

basics

~20 s

Move the write off the workload: policy-relevant labels are set by the deployment path from a reviewed declaration, never by the workload's own credential. Then reconcile against drift and staff it - issuance is now a service with an owner.

open as a page

A modality vendor demands a standing remote-support path or voids support: how do you grant it, and what does an intruder inherit?

level: seniorimportance: should knowfreq 38%

basics

~20 s

Grant it brokered and time-boxed rather than standing: the vendor terminates on a broker you control, the path opens on request and expires by itself. A permanent permit is a doorway an intruder inherits into the segment holding your widest exceptions.

open as a page

Segmenting a flat 4,000-host site into per-floor VLANs to contain an intruder hairpins east-west traffic through one firewall — what fills first?

level: seniorimportance: should knowfreq 50%

basics

~20 s

Usually the firewall's session table and connection-setup rate, plus an uplink now carrying every flow twice. And you cannot size it from flow records: the traffic you are relocating never crossed a routed hop, so none was ever exported.

open as a page

The resolver, directory and time services every segment must reach now sit behind an inspecting chokepoint, added after one segment was compromised — what does that cost you?

level: seniorimportance: should knowfreq 41%

basics

~20 s

It puts one device on every flow in the estate: latency on services that precede every other call, a failure domain wider than any segment, capacity sized for the aggregate, and a fail-open or fail-closed choice where both answers hurt.

open as a page

How do you order the change windows to move a zone's enforcement onto the real traffic path, when an intruder keeps the unfiltered path until the last one?

level: seniorimportance: should knowfreq 44%

basics

~20 s

Observe first, then move in the smallest reversible steps: build the permit set from real flows over a full business cycle, separate the routing change from the policy change, cut one zone pair or direction per night with a written rollback and a named owner, and accept that the gap stays open, with a dated end, until the last step.

open as a page

Your segmentation matrix has twelve zones and you can probe only a slice of the pairs - which?

level: seniorimportance: should knowfreq 37%

basics

~20 s

Measure directed pairs, not zones: twelve zones give 132 ordered source-to-destination pairs before you count services. Spend the budget on low-trust sources into high-value destinations, on pairs whose denial is an actual control claim, and on pairs a change touched - and show every untested pair as unknown.

open as a page

showing 1–30 of 44